Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Progress Software Corporation — Vulnerabilities & Security Advisories 101

Browse all 101 CVE security advisories affecting Progress Software Corporation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Progress Software Corporation develops enterprise software solutions, primarily focusing on application development platforms, database management, and IoT connectivity. The company’s product portfolio, including OpenEdge and Telerik components, has historically been associated with a significant volume of security vulnerabilities, currently totaling 86 CVEs. Common flaw categories include remote code execution, cross-site scripting, and privilege escalation, often stemming from input validation errors or improper access controls within legacy codebases. While no single catastrophic incident has defined the company’s public security history, the high CVE count suggests persistent challenges in maintaining secure coding practices across its diverse software suite. Security researchers frequently highlight these issues, urging administrators to apply patches promptly. The firm continues to address these vulnerabilities through regular updates, though the sheer number of recorded exploits indicates a complex attack surface requiring rigorous ongoing maintenance and vigilant configuration management by enterprise users.

CVE ID Title CVSS Severity Published
CVE-2026-65941 WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service. — WhatsUp Gold CWE-306 8.8 High 2026-08-12
CVE-2026-65940 WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server. — WhatsUp Gold CWE-732 6.8 Medium 2026-08-12
CVE-2026-65939 WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler. — WhatsUp Gold CWE-434 6.8 Medium 2026-08-12
CVE-2026-65938 WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API. — WhatsUp Gold CWE-862 4.3 Medium 2026-08-12
CVE-2026-65937 WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI — WhatsUp Gold CWE-79 8.0 High 2026-08-12
CVE-2026-9203 Server-side request forgery in Progress MarkLogic Server — MarkLogic Server CWE-918 8.5 High 2026-08-05
CVE-2026-9195 Cross-site scripting in Progress MarkLogic Server Query Console — MarkLogic Server CWE-79 9.3 Critical 2026-08-05
CVE-2026-9193 Privilege escalation in Progress MarkLogic Server Hadoop integration — MarkLogic Server CWE-269 9.9 Critical 2026-08-05
CVE-2026-9192 Authentication bypass in Progress MarkLogic Server ODBC App Server — MarkLogic Server CWE-287 9.8 Critical 2026-08-05
CVE-2026-9190 HTTP request smuggling in Progress MarkLogic Server — MarkLogic Server CWE-444 9.1 Critical 2026-08-05
CVE-2026-8709 Privilege escalation in Progress MarkLogic Server REST document patch operation — MarkLogic Server CWE-269 9.9 Critical 2026-08-05
CVE-2026-7557 SAML authentication bypass in Progress MarkLogic Server — MarkLogic Server CWE-347 9.1 Critical 2026-08-05
CVE-2026-7329 Privilege escalation in Progress MarkLogic Server REST query interfaces — MarkLogic Server CWE-269 9.9 Critical 2026-08-05
CVE-2026-7327 Privilege escalation in Progress MarkLogic Server REST API document processing — MarkLogic Server CWE-269 8.1 High 2026-08-05
CVE-2026-7326 Cross-site request forgery in Progress MarkLogic Server Admin UI — MarkLogic Server CWE-352 7.5 High 2026-08-05
CVE-2025-8095 Recoverable obfuscation using the OECH1 prefix encoding in OpenEdge — OpenEdge CWE-257 8.1 - 2026-04-14
CVE-2025-7389 Unauthorized Arbitrary File Read via RMI in AdminServer Interface — OpenEdge CWE-552 6.5 - 2026-04-14
CVE-2025-7388 Authenticated Command Injection via configuration parameter manipulation in exposed RMI interface — OpenEdge CWE-77 8.4 High 2025-09-04
CVE-2025-2572 WhatsUp Gold NmConfigurationManager.exe database manipulation vulnerability — WhatsUp Gold CWE-287 5.6 Medium 2025-04-14
CVE-2025-1968 Progress Sitefinity 代码问题漏洞 — Sitefinity CWE-613 7.7 High 2025-04-09
CVE-2024-6097 Absolute Path Traversal Vulnerability — Progress® Telerik® Reporting CWE-36 5.3 Medium 2025-02-12
CVE-2024-11626 Progress Sitefinity 安全漏洞 — Sitefinity CWE-79 8.4 High 2025-01-07
CVE-2024-11625 Progress Sitefinity 安全漏洞 — Sitefinity CWE-209 7.7 High 2025-01-07
CVE-2024-12105 WhatsUp Gold - SnmpExtendedActiveMonitor path traversal — WhatsUp Gold CWE-22 6.5 Medium 2024-12-31
CVE-2024-12106 WhatsUp Gold - LDAP configuration interface leading to allowing attacker to configure LDAP settings without authentication — WhatsUp Gold CWE-306 9.4 Critical 2024-12-31
CVE-2024-12108 WhatsUp Gold - Public API signing key rotation issue — WhatsUp Gold CWE-290 9.6 Critical 2024-12-31
CVE-2024-8785 WhatsUp Gold Registry Overwrite Remote Code Execution Vulnerability — WhatsUp Gold CWE-648 9.8 Critical 2024-12-02
CVE-2024-46909 WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability — WhatsUp Gold CWE-22 9.8 Critical 2024-12-02
CVE-2024-46905 WhatsUp Gold GetOrderByClause SQL Injection Privilege Escalation Vulnerability — WhatsUp Gold CWE-89 8.8 High 2024-12-02
CVE-2024-46906 WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerability — WhatsUp Gold CWE-89 8.8 High 2024-12-02

This page lists every published CVE security advisory associated with Progress Software Corporation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.